CVE-2023-41675
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
10/10/2023
Last modified:
07/11/2023
Description
A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.0.8 (including) |
| cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.0.10 (including) |
| cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | 7.2.0 (including) | 7.2.4 (including) |
To consult the complete list of CPE names with products and versions, see this page



